CWE-918
CVEs classified under CWE-918, newest first.
840 CVEsRSS
CVE-2026-15189Medium· 6.3A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23
A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such manipulation of the argument…
CVE-2026-0285Medium· 4.9A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…
A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to make unauthorized requests from the firewall to intern…
CVE-2026-53727HighRuby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
Ruby CSS Parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`
CVE-2026-59702Critical· 9.3PoCrepomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file://…
CVE-2026-59707High· 8.6PoCLocalAI - Server-Side Request Forgery via POST /models/apply
LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized gallery URL fields directly to galle…
CVE-2026-50127Medium· 5.9Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
CVE-2026-53513Critical· 9.6@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints
CVE-2026-34225Medium· 4.3Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
Open WebUI has Blind Server Side Request Forgery in its Image Edit Functionality
CVE-2026-33655High· 7.7New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
GHSA-qrwj-vh9x-gw5vHigh· 8.3Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CVE-2026-55787High· 7.1flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
CVE-2026-57987Medium· 6.5Microsoft Edge (Chromium-based) Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-58278Medium· 5.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-57993High· 7.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-22874Critical· 9.6PoCGitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-10055High· 8.5In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and return…
CVE-2026-11397Medium· 5.5The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action
The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_…
CVE-2026-45499Critical· 9.9Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
CVE-2026-57100Critical· 9.9Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVE-2026-9557Medium· 6.4Mautic Focus component Vulnerable to SSRF
Mautic Focus component Vulnerable to SSRF
CVE-2026-50288High@asymmetric-effort/specifyjs: URL parse failure silently allows request
@asymmetric-effort/specifyjs: URL parse failure silently allows request
GHSA-xw57-23p8-9wc5Medium@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
@asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range)
GHSA-2944-57xv-2682Medium@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
@asymmetric-effort/specifyjs: `data:` URI allowed without size restriction
GHSA-j5qp-p44g-2m49Medium@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
@asymmetric-effort/specifyjs: No redirect target validation in secureFetch
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
OpenClaw's browser act interactions could bypass private-network navigation checks
CVE-2026-50151Medium· 5.9oras-go: oras-go: Credential forwarding via unvalidated Location header during blob upload (CVE-2026-50151)
A flaw was found in oras-go. During the monolithic blob upload process, oras-go reuses the Authorization header for subsequent requests, even if a malicious registry provides a cross-host Location header. This vulnerability allows an attac…
GHSA-97vg-427p-8hx5Medium· 6.4SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
SurrealDB: Port-specific --deny-net rules silently bypassed on HTTP redirect
CVE-2026-44936Medium· 5.0Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
Rancher Fleet has SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml
CVE-2026-48978Loworas-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
CVE-2026-11714High· 8.5IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.
IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscovery-1.0 feature enabled.